Check home network security settings.
A flat pass rate treats every control as equally important, which it is not. Weighting critical failures heavily — twelve points each — and applying a large penalty when the wireless encryption itself is outdated produces a score that reflects actual exposure. A network passing most of its checklist but running WPA or an open guest network is not in reasonable shape, and the score should say so.
Weighted security score
Pass rate = passed / total x 100; score = pass rate - (critical failures x 12) - (25 if encryption is outdated), floored at 0
This score is a self-assessment aid, not a security audit. It cannot detect existing compromise or misconfiguration you have not identified. Seek professional assessment for networks handling sensitive data.
Default router password changed, firmware current, WPA3 or WPA2-AES only, WPS disabled, remote administration off, UPnP off unless needed, a separate guest and IoT network, DNS over an encrypted resolver, and no port forwards you cannot justify.
Anything that alone permits compromise: a default or reused admin password, remote administration exposed to the internet, unpatched firmware with a known exploit, WPS enabled, or an open network with no encryption.
WPA2 with AES-CCMP remains adequate for home use. What must be avoided is WPA2 with TKIP, WPA1 and WEP, all of which are practically breakable. WPA3 adds protection against offline password guessing and is preferable where all devices support it.